CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks
Key Takeaways A critical code injection vulnerability in Craft CMS (CVE-2025-32432) is under active exploitation. The flaw allows unauthenticated remote code execution, granting attackers full...
Key Takeaways
- A critical code injection vulnerability in Craft CMS (CVE-2025-32432) is under active exploitation.
- The flaw allows unauthenticated remote code execution, granting attackers full control over affected systems.
- CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, emphasizing its immediate threat.
- Organizations using Craft CMS must apply security updates without delay.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning regarding active exploitation of a severe code injection vulnerability, identified as CVE-2025-32432, in the popular Craft CMS platform. The flaw’s inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog confirms its active weaponization by threat actors, necessitating immediate action from all affected organizations.
Table Of Content
Understanding the Vulnerability
Categorized under CWE-94, which details improper control of code generation, CVE-2025-32432 is a critical code injection vulnerability. This type of security weakness arises when an application fails to adequately sanitize or validate user-provided input before processing it as executable commands. For Craft CMS, a widely adopted and highly customizable content management system, this oversight presents a grave risk.
The vulnerability enables a remote, unauthenticated attacker to execute arbitrary code directly on the server hosting the Craft CMS instance. Successful exploitation grants complete control over the compromised application, allowing threat actors to manipulate website content, extract sensitive database records, or establish persistent backdoors. Furthermore, a compromised web server can serve as a strategic foothold for attackers to pivot laterally into an organization’s internal network, escalating the potential damage significantly.
Active Exploitation and CISA’s Mandate
CISA officially added CVE-2025-32432 to its KEV catalog on March 20, 2026, signaling that this vulnerability is actively being leveraged in real-world attacks. While CISA has not yet confirmed whether this specific flaw is being used in ongoing ransomware campaigns, the agency underscores that code injection and remote code execution vulnerabilities are highly prized by various threat actors, including state-sponsored groups and initial access brokers. Organizations utilizing Craft CMS must therefore treat this as an urgent, high-priority threat.
Unpatched content management systems that are accessible via the internet are particularly vulnerable and are likely already being targeted by automated scanning and exploitation tools.
What You Should Do
- Apply Patches Immediately: All organizations using Craft CMS must apply the latest security updates provided by the vendor without delay.
- Monitor Logs: Actively monitor web access logs for any unusual behavior, unauthorized administrative attempts, or indicators of compromise.
- Implement Temporary Mitigations: If immediate patching is not feasible, follow applicable cloud service security guidance or temporarily disable the vulnerable product until secure mitigations can be fully implemented.
- Adhere to CISA Guidance: While CISA’s Binding Operational Directive (BOD) 22-01 legally mandates federal civilian executive branch agencies to remediate this vulnerability by April 3, 2026, CISA strongly urges all private-sector entities and global enterprises to adopt the same aggressive patching timeline.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.